CVE-2026-42842 Details
Description
The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Grav CMS Form plugin's select field template. Taxonomy tag and category values are rendered with the Twig |raw filter in the admin panel, bypassing the global autoescape protection. An editor-level user can inject arbitrary JavaScript that executes in any administrator's browser session when they view or edit any page in the admin panel. This vulnerability is fixed in 9.1.0.
A stored cross-site scripting vulnerability has been identified in the Grav CMS Form plugin, specifically in the select field template. This issue affects versions prior to 9.1.0. The vulnerability arises because taxonomy tag and category values are rendered using the Twig |raw filter in the admin panel, which bypasses the global autoescape protection. As a result, an editor-level user can inject arbitrary JavaScript that executes in the browser session of any administrator who views or edits a page in the admin panel. The vulnerability is cross-page, as a malicious taxonomy value can impact the entire admin panel.
Users can update to Grav Form Plugin version 9.1.0 or later, and Grav CMS version 2.0.0-beta.2 or later, to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getgrav/grav/security/advisories/GHSA-c2q3-p4jr-c55f | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/getgrav/grav-plugin-form/commit/6bffb4c98be468a155d1656544ec45bb4a443957 | [email protected] | Source CodeVendor |
| https://github.com/getgrav/grav/security/advisories/GHSA-c2q3-p4jr-c55f | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Grav | < 2.0.0-beta.2 (semver) |
CPE
Remediation
| |
| Grav | All versions |
CPE
Remediation
| |
| Grav | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion